Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
lfi vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2022-45926
An issue exists in OpenText Content Suite Platform 22.1 (16.2.19.1803). The endpoint notify.localizeEmailTemplate allows a low-privilege user to evaluate webreports.
Opentext Opentext Extended Ecm
NA
CVE-2022-45928
A remote OScript execution issue exists in OpenText Content Suite Platform 22.1 (16.2.19.1803). Multiple endpoints allow the user to pass the parameter htmlFile, which is included in the HTML output rendering pipeline of a request. Because the Content Server evaluates and execute...
Opentext Opentext Extended Ecm
6.8
CVSSv2
CVE-2019-11590
The 10Web Form Maker plugin prior to 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclusion via directory traversal, because there can be a discrepancy between the $_POST['action'] value and the $_GET['...
10web Form Maker
7.8
CVSSv2
CVE-2020-14864
Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation). Supported versions that are affected are 5.5.0.0.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with...
Oracle Business Intelligence 12.2.1.3.0
Oracle Business Intelligence 12.2.1.4.0
Oracle Business Intelligence 5.5.0.0.0
NA
CVE-2023-26609
ABUS TVIP 20000-21150 devices allows remote malicious users to execute arbitrary code via shell metacharacters in the /cgi-bin/mft/wireless_mft ap field.
Abus Tvip 20000-21150 Firmware -
1 Github repository
6.8
CVSSv2
CVE-2012-5698
BabyGekko prior to 1.2.4 has SQL injection.
Babygekko Babygekko
1 EDB exploit
7.5
CVSSv2
CVE-2012-5699
BabyGekko prior to 1.2.4 allows PHP file inclusion.
Babygekko Babygekko
1 EDB exploit
4.3
CVSSv2
CVE-2012-5700
Multiple cross-site scripting (XSS) vulnerabilities in Baby Gekko prior to 1.2.2f allow remote malicious users to inject arbitrary web script or HTML via the (1) id parameter to admin/index.php or the (2) username or (3) password parameter in blocks/loginbox/loginbox.template.php...
Babygekko Baby Gekko 1.0.1
Babygekko Baby Gekko 0.90
Babygekko Baby Gekko 1.0.0
Babygekko Baby Gekko 1.1.1
Babygekko Baby Gekko 0.99
Babygekko Baby Gekko 1.2.2
Babygekko Baby Gekko 1.2.0
Babygekko Baby Gekko
Babygekko Baby Gekko 1.1.2
Babygekko Baby Gekko 1.1.4
Babygekko Baby Gekko 1.1.3
Babygekko Baby Gekko 1.1.0
Babygekko Baby Gekko 0.91
Babygekko Baby Gekko 1.1.5
Babygekko Baby Gekko 0.98
1 EDB exploit
5
CVSSv2
CVE-2017-6100
tcpdf prior to 6.2.0 uploads files from the server generating PDF-files to an external FTP.
Tcpdf Project Tcpdf
4.3
CVSSv2
CVE-2013-1646
Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange Server prior to 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 allow remote malicious users to inject arbitrary web script or HTML via (1) invalid JSON data in a mail-sending POST request, (2) an arbi...
Open-xchange Open-xchange Server 6.22.1
Open-xchange Open-xchange Server 6.20.7
Open-xchange Open-xchange Server 6.22.0
1 EDB exploit
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
logic flaw
CVE-2024-23692
CVE-2024-26229
CVE-2024-35255
CVE-2024-5835
CVE-2024-5837
XML external entity
dos
CVE-2024-5813
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
NEXT »